• 1 Post
  • 7 Comments
Joined 2 years ago
cake
Cake day: July 14th, 2023

help-circle
  • I am familiar with these alternatives. My experiment was specific in wanting FIDO2 and I ended up figuring out the issue. It was the intersection of a couple of weird behaviours that made debugging very confusing, but it works exactly as I expected it would once those are resolved. I guess we can consider this a proof of concept that you can indeed use FIDO2 tokens as an external SSH host key (though as I said below whether this is practically useful is another matter entirely).





  • Yeah, the rough idea is to use any old FIDO2 key as a USB HSM. Not necessarily looking for a very practical solution (the easy fix would be to just encrypt the drive), but curious. What inspired this, though not necessarily the final application, is Nix secret distribution tools that use the host key as the secret recipient. This means that theoretically if you have the host identity tied to an external HSM or similar you could have the same image deploy as different machines based on what security key you have plugged in.




  • As others have said, it is not entirely clear what you mean by sharp. Based on the rounded corner and button example you gave previously, I think it might just be the graphic design. MacOS has had a lot of time invested into its design language including subtle things like a thin, almost glass-like specular border around windows and then a drop shadow. This very much becomes a matter of taste in many cases, but for some it helps identify boundaries more precisely. Perhaps have a look at https://github.com/vinceliuice/WhiteSur-gtk-theme, which replicates MacOS as closely as possible. You may be able to experiment with it side by side and see if you can figure out exactly what design element it is that you are looking for.